|
131
|
- |
|
-
|
-
|
Lack of input filtering leads to an XSS vector in the HTML filter code.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48905
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
- |
|
-
|
-
|
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48904
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
- |
|
-
|
-
|
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48903
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
- |
|
-
|
-
|
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
New
|
-
|
CVE-2026-48902
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
- |
|
-
|
-
|
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
New
|
-
|
CVE-2026-48901
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
- |
|
-
|
-
|
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48900
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
- |
|
-
|
-
|
An improper access check allows privilege escalation through the com_users batch task.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48899
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
- |
|
-
|
-
|
An improper access check allows privilege escalation through the com_users batch task.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48898
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
- |
|
-
|
-
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
New
|
CWE-287
Improper Authentication
|
CVE-2026-48897
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
- |
|
-
|
-
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
New
|
CWE-287
Improper Authentication
|
CVE-2026-48896
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|